Conversation
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Copilot review overview
Review effort: Lite
Findings: 1
Open (5)
i2c_stop() treatsSCB_INTR_M_I2C_BUS_ERRORthe same as STOP because it returns thei2c_wait_m()… · Newflash_rowis sized forPSOC_C3_FLASH_ROW_WORDS(data + 16 bytes of col33 metadata), but only… · New These barrier macros lack a\"memory\"clobber, so the compiler is free to reorder memory… · New The output section name.edidxlooks like a typo/slip from the conventional.ARM.exidx(or… · New In C,mainis specified to returnint. Even for bare-metal test apps, usingint main(void)… · New
What changed in this PR
Adds a new bare-metal wolfBoot target for Infineon PSOC Control C3, including HAL/linker support, serial back-ends (SPI/I2C), and TPM-over-I2C support.
Changes:
- Added PSOC C3 HAL (register defs, flash via BootROM table, pin/peripheral clock setup) plus linker scripts and test application support.
- Added SPI and I2C SCB drivers, a generic
i2c_drv.hinterface, and TPM TIS-over-I2C transport option (WOLFBOOT_TPM_I2C). - Added docs, CI build jobs, and a host unit test for the fractional divider math.
| File | Description |
|---|---|
| tools/unit-tests/unit-psoc-c3-divider.c | Adds a host unit test for PSOC C3 16.5 divider math. |
| tools/unit-tests/Makefile | Registers and builds the new PSOC C3 divider unit test. |
| test-app/app_psoc_c3.c | Adds a bare-metal PSOC C3 test app exercising A/B update flow. |
| test-app/Makefile | Adds psoc_c3 target settings (CPU flags, linker script selection). |
| test-app/ARM-psoc_c3.ld | Adds a PSOC C3 test application linker script template. |
| src/tpm.c | Adds TPM TIS-over-I2C transport + fixes advanced IO callback signature types. |
| options.mk | Wires WOLFBOOT_TPM_I2C build option to select the I2C backend and ADV_IO. |
| include/spi_drv.h | Adds PSOC C3 SPI backend include + declares SPI helpers for TPM-only builds. |
| include/i2c_drv.h | Introduces a generic I2C master driver interface for TPM-over-I2C. |
| hal/spi/spi_drv_psoc_c3.h | Defines PSOC C3 SPI pinout/clocking configuration defaults. |
| hal/spi/spi_drv_psoc_c3.c | Implements PSOC C3 SPI driver with bounded FIFO waits and TPM xfer support. |
| hal/psoc_c3.ld | Adds PSOC C3 wolfBoot linker script (flash/RAM regions, sections). |
| hal/psoc_c3.h | Adds PSOC C3 register definitions and divider computation helper. |
| hal/psoc_c3.c | Implements PSOC C3 HAL (flash ops via BootROM, clocks, pins, UART, boot prep). |
| hal/i2c/i2c_drv_sim.c | Adds simulator stub I2C backend for build-testing TPM-over-I2C path. |
| hal/i2c/i2c_drv_psoc_c3.h | Defines PSOC C3 I2C pinout/clocking configuration defaults. |
| hal/i2c/i2c_drv_psoc_c3.c | Implements PSOC C3 I2C master driver (polled, bounded waits). |
| docs/Targets.md | Documents PSOC Control C3 port, memory aliases, flash behavior, build/flash steps. |
| docs/TPM.md | Documents WOLFBOOT_TPM_I2C option and its build implications. |
| config/examples/psoc_c3.config | Adds example config for PSOC C3 including erased-flash behavior settings. |
| arch.mk | Adds psoc_c3 target block, wiring defaults, and I2C target selection. |
| Makefile | Extends clean/cppcheck to cover new hal/i2c sources/objects. |
| .gitignore | Ignores the new unit test binary artifact. |
| .github/workflows/test-configs.yml | Adds CI build jobs for PSOC C3 configs and TPM SPI/I2C variants. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Copilot review overview
Review effort: Lite
Findings: 1
Open (5)
hal/psoc_c3.hdefines ARM-only barrier inline asm (dmb/dsb/isb). Including that header in a… · New The include guard macro_PSOC_C3_H_uses an identifier pattern reserved to the implementation… · New The output section name.edidxlooks like a typo for the conventional.ARM.exidx(or at least… · New Theseprintfformat specifiers assumeuint32_tisunsigned int(%u). For portability across… · New Theseprintfformat specifiers assumeuint32_tisunsigned int(%u). For portability across… · New
Resolved since last review (5)
i2c_stop() treatsSCB_INTR_M_I2C_BUS_ERRORthe same as STOP because it returns thei2c_wait_m()… These barrier macros lack a\"memory\"clobber, so the compiler is free to reorder memory…flash_rowis sized forPSOC_C3_FLASH_ROW_WORDS(data + 16 bytes of col33 metadata), but only… In C,mainis specified to returnint. Even for bare-metal test apps, usingint main(void)… The output section name.edidxlooks like a typo/slip from the conventional.ARM.exidx(or…
| #include "../../hal/psoc_c3.h" | ||
|
|
| #ifndef _PSOC_C3_H_ | ||
| #define _PSOC_C3_H_ |
| .edidx : | ||
| { | ||
| . = ALIGN(4); | ||
| *(.ARM.exidx*) | ||
| } > FLASH |
| printf("FAIL %s: pclk=%u target=%u -> int=%u frac=%u, expected %u/%u\n", | ||
| what, pclk, target, i, f, exp_i, exp_f); |
| printf("ok %s: int=%u frac=%u -> %u Hz\n", what, i, f, | ||
| produced(pclk, i, f)); |



The PSOC Control C3 family (PSC3, CAT1B) is an Arm Cortex-M33 motor-control MCU. wolfBoot runs as the first application the BootROM launches, verifies the signed firmware and boots it. The port is bare metal: no Peripheral Driver Library, no BSP and no generated configuration, so it builds with an
arm-none-eabitoolchain alone.What it adds
hal/psoc_c3.{c,h,ld}- HAL, register definitions and linker scripthal/spi/spi_drv_psoc_c3.{c,h},hal/i2c/i2c_drv_psoc_c3.{c,h}- SCB serial back-endsinclude/i2c_drv.h- a generic I2C master interface, which wolfBoot did not previously haveconfig/examples/psoc_c3.configwith-128k,-tpm(SPI) and-tpm-i2cvariants, and a CI job for eacharch.mktarget block,test-app/app_psoc_c3.cand its linker script, and a host unit test for the clock dividerTouches shared code
src/tpm.c- adds a TIS-over-I2C transport beside the existing SPI one, selected byWOLFBOOT_TPM_I2Cand documented indocs/TPM.md. Also corrects the advanced-IO callback signature, which declaredintwhereTPM2HalIoCbusesINT32, so the callback could not be assigned towolfTPM2_Init().include/spi_drv.h- target arm for the new back-end, and widens thespi_cs_on/spi_cs_off/spi_write/spi_readprototype guard to cover TPM-only builds, where those functions are defined but were not declared.options.mk- selects the I2C back-end whenWOLFBOOT_TPM_I2Cis set.Three properties of this family shape the port:
0x00, not0xFF, so the configs setFLAGS_INVERT=1andNVM_FLASH_WRITEONCE=0. Without the inverted polarity the state written bywolfBoot_update_trigger()cannot be told apart from erased flash and no update is taken.HSIOM_SECURE_PRTbefore its HSIOM and GPIO registers accept a write at all.Hardware / test status
Validated end to end on a PSOC Control C3 evaluation kit fitted with a C3M6 (on-board SEGGER J-Link, console 115200 8N1): console output, image integrity and ECC256 signature verification, the handoff to the application, and a full A/B update in which the application triggers an update, wolfBoot swaps the partitions through the swap sector, and the new version confirms success.
The 128 KB layout and the other family members are build-tested only; flash size is the only geometry that differs across the family.